×êÑÐÈËÔ±Åû¶TCP/IPÖÐͳ³ÆÎªINFRA:HALTµÄ14¸ö·ì϶£»£»£»£»£»£»£»£»Òâ´óÀûÀÆë°Â´óÇøÏ°È¾ÀÕË÷Èí¼þRansomEXXÍøÂçÖжÏ
°ä²¼¹¦·ò 2021-08-05
×êÑÐÈËÔ±Åû¶ÁËÔÚNicheStack TCP/IP²Ö¿âÖз¢ÏÖµÄͳ³ÆÎªINFRA:HALTµÄ14¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˳¬¹ý200¼Ò¹©¸øÉÌÔì×÷µÄOTÉ豸¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶Äܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ (DoS)ºÍÐÅϢй¶¡¢TCPºýŪºÍDNS»º´æÖж¾¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ΪCVE-2020-25928ºÍCVE-2020-31226£¬£¬£¬£¬£¬£¬ÆÀ·Ö±ðÀëΪ9.8ºÍ9.1£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˲ֿâµÄDNS¿Í»§¶ËºÍHTTP·þÎñÆ÷×é¼þ£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚÖ¸±êÉ豸ÉÏÖ´ÐдúÂë²¢ÆëÈ«½ÚÔìËü¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/08/critical-flaws-affect-embedded-tcpip.html
2.Google°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´AndroidÖеÄ30¶à¸ö·ì϶

Google°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËAndroidÖеÄ30¶à¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇýÌå¿ò¼ÜÖеÄCVE-2021-0519£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚAndroid 8.1ºÍ9°æ±¾µÄÉ豸ÉÏÌáȨ£¬£¬£¬£¬£¬£¬»òµ¼ÖÂAndroid 10ºÍ11ÉϵÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Õâ´Î¸üл¹»¹½¨¸´Á˸ßͨ×é¼þºÍ¸ßͨ¹ØÔ´×é¼þÖжà¸öÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬CVE-2021-1972¡¢CVE-2021-1976¡¢CVE-2021-1916ºÍCVE-2021-1919µÈ·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-patches-high-risk-android-security-flaws
3.Òâ´óÀûÀÆë°Â´óÇøÏ°È¾ÀÕË÷Èí¼þRansomEXXÍøÂçÖжÏ

ÉÏÖÜÈÕÔ糿£¬£¬£¬£¬£¬£¬Òâ´óÀûÀÆë°Â´óÇøÔâµ½ÀÕË÷Èí¼þRansomEXX¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼ÓÃÜÁËÆäÊý¾ÝÖÐÐĵÄËùÓÐÎļþ²¢ÖжÏÁËITÍøÂ磬£¬£¬£¬£¬£¬»¹Ó°ÏìÁËÆäCOVID-19ÒßÃç½ÓÖֵǼÇÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßÊÇËÒÔ¼°ËûÃǵÄÖ¸±êÊÇʲô£¬£¬£¬£¬£¬£¬Í¨³£ÀÕË÷ÍÅ»ï»áÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡Êý¾Ý×÷ΪÀÕË÷µÄ³ïÂ룬£¬£¬£¬£¬£¬µ«¸ÃµØÓòµÄ½¡È«¡¢²ÆÕþºÍÔ¤ËãÊý¾Ý¶¼Êǰ²È«µÄ¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³ÆÕâ´Î¹¥»÷À´×ÔRansomEXX£¬£¬£¬£¬£¬£¬ÓÉÓÚÊê½ð¼Í¼ÖÐÓÃÀ´ÓëºÚ¿Í½»ÉæµÄ°µÍøÁ´½ÓÊǸÃÍÅ»ïµÄTorÍøÕ¾£»£»£»£»£»£»£»£»µ«×êÑÐÈËÔ±JAMESWT³Æ£¬£¬£¬£¬£¬£¬Òâ´óÀûÓÐÖ¤¾ÝÅú×¢¹¥»÷ÊÇÓÉLockBit 2.0½øÐе쬣¬£¬£¬£¬£¬Ä¿Ç°ÎÞ·¨·ÖÏí¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-attack-hits-italys-lazio-region-affects-covid-19-site/
4.ÃÀ¹ú·çͶ¹«Ë¾ATV³ÆÆäϰȾÀÕË÷Èí¼þй¶¿Í»§Ó×ÎÒÐÅÏ¢

ÃÀ¹ú·çÏÕͶ×ʹ«Ë¾Advanced Technology Ventures£¨ATV£©³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ATV³Æ£¬£¬£¬£¬£¬£¬2021Äê7ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾´ÓÆäµÚÈý·½¹©¸øÉÌ´¦»ñϤ£¬£¬£¬£¬£¬£¬¹«Ë¾´æ´¢²ÆÕþ»ã±¨ÐÅÏ¢µÄÁ½Ì¨·þÎñÆ÷Ôâµ½ÁËÀÕË÷¹¥»÷ÇÒÊý¾Ý±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£7ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨ÕâЩÊý¾ÝÔâµ½ÁËδ¾ÊÚȨµÄ½Ó¼ûºÍй¶¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»¹Ð¹Â¶Á˲¿ÃÅÓû§µÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍÉç»á°²È«ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/120816/data-breach/advanced-technology-ventures-ransomware-attack.html
5.½üÆÚLemonDuckµÄhands-on-keyboard¹¥»÷»î¶¯Ôö³¤

×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬½üÆÚLemonDuckµÄhands-on-keyboard¹¥»÷»î¶¯Ôö³¤¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÓÚ2019ÄêÉϰëÄêÓÉÒÔÉ«Áа²È«¹«Ë¾Guardicore³õ´Î·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰµÄÁ½ÄêÀ£¬£¬£¬£¬£¬ÒѾºÜÓ×µÄÍÚ¿ó¶ñÒâÈí¼þÒѾÑÝÔì³ÉÒ»¸öÖØ´óµÄ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬²¢ÇÒ½üÆÚÔÚ³¢ÊÔͨ¹ýÊÖ¶¯¹¥»÷±»ÈëÇÖµÄÍøÂ磬£¬£¬£¬£¬£¬×êÑÐÈËÔ±³ÆÕâÊÇÒ»¸öΣÏÕµÄת±ä¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Î¢Èí»¹°ÑÎȵ½£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÆðÍ·ÔÚËûÃÇÈëÇÖµÄϵͳÉÏ×°ÖÃÆäËû¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÈçRamnitµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/lemonduck-botnet-evolves-to-allow-hands-on-keyboard-intrusions/
6.ÃÀ¹úNSAºÍCISA½áºÏ°ä²¼ÓйØKubernetes¼Ó¹ÌµÄÖ¸ÄÏ

ÃÀ¹úNSAºÍCISA½áºÏ°ä²¼ÁËÓйØKubernetes¼Ó¹ÌµÄÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¡£KubernetesÊÇÒ»ÖÖ¿ªÔ´ÈÝÆ÷±àÅÅϵͳ£¬£¬£¬£¬£¬£¬ÓÃÓÚ×Ô¶¯²¿Êð¡¢À©´óºÍÖÎÀíÈÝÆ÷»¯ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏΪϵͳÖÎÀíÔ±Ìṩһ¸ö°²È«»ù×¼£¬£¬£¬£¬£¬£¬ÓÃÀ´¶ÔKubernetes½øÐÐÅäÖÃÒÔÕмܸ÷ÖÖÀàÐ͵Ĺ¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Ö¸ÄÏ»¹¾ßÌå½éÉÜÁ˹«Ë¾ºÍµ±¾Ö»ú¹¹Äܹ»Ö´Ðеĸù»ù»º½â´ëÊ©£¬£¬£¬£¬£¬£¬Ô̺¬£ºÉ¨ÃèÈÝÆ÷ºÍPodÒÔÈ·ÈÏÊÇ·ñ´æÔÚ·ì϶»òÃýÎóÅäÖ㻣»£»£»£»£»£»£»ÒÔ¾¡¿ÉÄÜÉÙµÄȨÏÞÔËÐÐÈÝÆ÷ºÍPod£»£»£»£»£»£»£»£»Ê¹ÓÃÈÕÖ¾ÉóºËµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/08/02/cisa-and-nsa-release-kubernetes-hardening-guidance


¾©¹«Íø°²±¸11010802024551ºÅ